QIZ may revise these Terms from time to time in its sole discretion. Material changes will be posted at this URL with an updated effective date. Continued use of the Software after an update constitutes acceptance of the revised Terms. Changes apply prospectively only.
“Control Plane” means the QIZ component responsible for ingesting data from Collectors, normalizing it into the unified inventory, evaluating Policy rules, generating Issues, and exposing the QIZ user interface.
“Collector” means the QIZ component(s) that gather cryptographic configuration and related infrastructure data from Customer's environment — whether via integration with existing tools, direct querying of infrastructure APIs, or native probing of endpoints — and transmit normalized data to the Control Plane.
“Software” means the QIZ Control Plane, Collectors, and any related documentation, updates, or components made available by QIZ, regardless of deployment model (cloud, on-premises, hybrid, outpost, or air-gapped).
“Cryptographic Data” means data relating to cryptographic materials, keys, certificates, protocols, cipher suites, and related configuration state discovered or collected by the Software from Customer's environment.
“Customer Data” means Cryptographic Data together with any other technical, configuration, topology, network, or contextual data collected from Customer's environment by the Software. Customer Data is technical/infrastructure data and does not include Personal Data about individuals, except where incidentally embedded in configuration metadata as described in Section 6.
“Documentation” means QIZ's end-user technical documentation for the Software, as updated from time to time.
Subject to these Terms and any applicable order form or subscription, QIZ grants Customer a non-exclusive, non-transferable, non-sublicensable license to install, deploy, and use the Software solely for Customer's own internal cryptographic posture management and observability purposes, for the duration of Customer's valid subscription or evaluation period, and in the deployment model(s) (cloud, on-premises, hybrid, outpost, or air-gapped) agreed with QIZ.
Customer shall not, and shall not permit any third party to:
The Software may incorporate third-party and open-source components.
3.4 Ownership
The Software is licensed, not sold. QIZ and its licensors retain all right, title, and interest in and to the Software, including all intellectual property rights. No rights are granted to Customer other than those expressly set out in these Terms.
Customer may deploy the Software in any deployment model made available by QIZ and agreed in the applicable order (cloud, on-premises, hybrid, outpost-based, or fully air-gapped). Regardless of deployment model, Customer remains responsible for the security, configuration, and lawful operation of the systems on which Collectors are installed, and for ensuring it has the right to permit QIZ's Collectors to access those systems.
Customer represents and warrants that it:
Customer Data, as collected and processed by the Software, consists of technical and infrastructure information — cryptographic materials, certificates, protocols, cipher suites, network topology, and related configuration and dependency data — and does not include Personal Data about Customer's employees, end users, or other individuals, except to the extent such information is incidentally embedded in configuration metadata (for example, an email address in a certificate field or a hostname). QIZ does not collect, and the Software is not designed to collect, information about individuals for its own sake.
QIZ processes Customer Data to: (i) operate, maintain, and provide the Software to Customer, including generating Inventory, Policy evaluations, Issues, and Root Cause Analysis; and (ii) diagnose and resolve technical problems with the Software.
QIZ will not sell Customer Data. In the rare event any Personal Data is incidentally processed as described above, it is handled in accordance with qizsecurity.com/privacy-policy and, where applicable, a separate Data Processing Agreement.
EXCEPT AS EXPRESSLY STATED IN AN APPLICABLE ORDER FORM OR MASTER SERVICES AGREEMENT, THE SOFTWARE IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. QIZ DOES NOT WARRANT THAT THE SOFTWARE WILL IDENTIFY, DETECT, OR REMEDIATE ALL CRYPTOGRAPHIC WEAKNESSES, MISCONFIGURATIONS, OR VULNERABILITIES IN CUSTOMER'S ENVIRONMENT, AND CUSTOMER REMAINS RESPONSIBLE FOR ITS OWN SECURITY POSTURE AND DECISIONS.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, QIZ SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR RELATED TO THE SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. EXCEPT FOR CLAIMS ARISING FROM (I) A PARTY'S BREACH OF ITS CONFIDENTIALITY OBLIGATIONS, OR (II) A PARTY'S GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR FRAUD, QIZ'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE SOFTWARE SHALL NOT EXCEED THE FEES PAID BY CUSTOMER TO QIZ UNDER THE APPLICABLE ORDER IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
Customer shall comply with all applicable laws in its use of the Software, including export control, sanctions, and anti-corruption laws. Customer represents that it is not located in, and is not a national or resident of, any country subject to comprehensive U.S. or EU trade sanctions, and is not on any restricted-party list maintained by the U.S. Department of Commerce or Treasury.
These Terms are governed by the laws of the State of Delaware, without regard to conflict-of-laws principles. The parties submit to the exclusive jurisdiction of the state and federal courts located in Delaware for any dispute arising under these Terms.